b4n1shed's Avatar

b4n1shed

@b4n1shed.bsky.social

Security Research, Threat Intelligence, Malware Analysis, Embedded Systems, Misc. Hackery and Shenanigans.

354 Followers  |  756 Following  |  31 Posts  |  Joined: 26.06.2023  |  2.3116

Latest posts by b4n1shed.bsky.social on Bluesky

Preview
New Malvertising Attack Spreads Crypto Stealing PS1Bot Malware Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

🚨 Watch out as the new #PS1Bot malware steals crypto wallets, passwords, and sensitive data, spreading through #malvertising while evading detection.

Read: hackread.com/malvertising...

#CyberSecurity #Malware #Crypto #Keylogger

14.08.2025 21:15 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
New PS1Bot Malware Campaign Uses Malvertising to Deploy Multi-Stage In-Memory Attacks PS1Bot malvertising campaign uses in-memory PowerShell attacks since early 2025, enabling stealth data theft.

New PS1Bot Malware Campaign Uses Malvertising to Deploy Multi-Stage In-Memory Attacks thehackernews.com/2025/08/new-... via @thehackernews.bsky.social

13.08.2025 16:13 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Malvertising campaign leads to PS1Bot, a multi-stage malware framework Cisco Talos has observed an ongoing malware campaign that seeks to infect victims with a multi-stage malware framework, implemented in PowerShell and C#, which we are referring to as β€œPS1Bot.”

Excited to announce that we just published our research into "PS1Bot" a multi-stage PowerShell-based modular malware framework being delivered via malvertising campaigns that we've been tracking throughout 2025. Check it out!

blog.talosintelligence.com/ps1bot-malve...

#malware #stealer

12.08.2025 20:12 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
You Wouldn’t Download A Skateboard? Hackaday Article

You Wouldn’t Download A Skateboard?

30.05.2025 23:02 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Attacker Specialization Puts Threat Modeling on Defensive Specialization among threat groups poses challenges for defenders, who now must distinguish between different actors responsible for different facets of an attack.

Attacker Specialization Puts Threat Modeling on Defensive

www.darkreading.com/threat-intel...

16.05.2025 21:02 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Researchers Unveil New Mechanism to Track Compartmentalized Cyber Threats Cisco Talos, in collaboration with The Vertex Project, has introduced an innovative approach to tackle the rising complexity.

Researchers Unveil New Mechanism to Track Compartmentalized Cyber Threats gbhackers.com/new-mechanis...

14.05.2025 14:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
An unnlocked padlock being exchanged in front of a desktop computer screen.

An unnlocked padlock being exchanged in front of a desktop computer screen.

Attack kill chains are evolving, and defenders must, too. In this two-part blog, Talos examines how threat actors are working together like never before, and proposes an extension to the Diamond Model: http://cs.co/63324NVHbE

13.05.2025 14:54 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Huge thanks to @vertexproject.bsky.social for updating Synapse to support the new "relationship" context.
We’re excited to see this research foster collaboration and push real change across the threat intelligence community. (3/3)

13.05.2025 13:02 β€” πŸ‘ 3    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0
Preview
Defining a new methodology for modeling and tracking compartmentalized threats How do you profile actors and defend your systems when multiple threat actors are working together? In Part 2, Cisco Talos proposes an extended Diamond Model to analyze complex relationships between a...

In blog 2, we dive into the challenges of investigating compartmentalized campaigns. We share our approach to identifying them and propose an extended Diamond Model with a new "relationship" layer to close the analytical gaps. (2/3)
blog.talosintelligence.com/compartmenta...

13.05.2025 13:02 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

πŸ“‘ New blogs out: Compartmentalized attacks are no longer limited to financially motivated actors, state-sponsored groups are adopting them too. We propose a new taxonomy for initial access groups to reflect broader motivations and affiliations. (1/3)

13.05.2025 13:02 β€” πŸ‘ 6    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0

In addition, we have also published a blog proposing an extension to the Diamond Model to support more accurate and comprehensive threat modeling support for compartmentalized intrusion sets. Check it out too!

blog.talosintelligence.com/compartmenta...

13.05.2025 12:52 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Redefining IABs: Impacts of compartmentalization on threat tracking and modeling Threat actors are teaming up, splitting attacks into stages and making defense harder than ever. In Part 1, Cisco Talos examines their tactics and defines their motivations.

Excited to announce that Asheer Malhotra, @ashl3y-shen.bsky.social, @vventura.bsky.social and I just published a new blog on how initial access groups are changing and propose a new taxonomy to support the latest threats that we are seeing. Check it out!

blog.talosintelligence.com/redefining-i...

13.05.2025 12:50 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 2

Come catch @infosec-nick.bsky.social and I in DC this coming week to talk compartmentalized intrusions!

11.05.2025 20:10 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Spam campaign targeting Brazil abuses Remote Monitoring and Management tools A new spam campaign is targeting Brazilian users with a clever twist β€” abusing the free trial period of trusted remote monitoring tools and the country’s electronic invoice system to spread malicious ...

Spam campaign targeting Brazil abuses Remote Monitoring and Management tools blog.talosintelligence.com/spam-campaig...

11.05.2025 20:08 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Excited to announce that @infosec-nick.bsky.social and I will be presenting on compartmentalization in cyber threats at the CTA TIPS conference next month! Come check it out!

15.04.2025 14:41 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Come join us at the Ask A Security Expert session at Black Hat Asia on April 4th! I'll be there with Orange Tsai, Ryan Flores, and Dr. Marina Krotofil answering your cybersecurity questions. Submit your topics in advance using the form on the event page. Looking forward to seeing you there!

24.03.2025 16:04 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Preview
Physical Key Copying Starts With A Flipper Zero A moment’s inattention is all it takes to gather the information needed to make a physical copy of a key. It’s not necessarily an easy process, though, so if pen testing is your game, s…

Physical Key Copying Starts With A Flipper Zero hackaday.com/2025/03/25/p...

26.03.2025 12:41 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
abuse.ch - Figthing malware and botnets abuse.ch is providing community driven threat intelligence on cyber threats

Introducing: abuse.ch Hunting Platform abuse.ch/blog/introdu...

17.03.2025 13:26 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
2600 TWITTER ACCOUNT FROZEN OVER DOGE CONTACT LIST | 2600

We are now hosting the DOGE contact list locally. www.2600.com/content/2600...

12.03.2025 19:13 β€” πŸ‘ 68    πŸ” 29    πŸ’¬ 3    πŸ“Œ 1

I am really proud and humbled for being accepted at Pivot on. This was a team effort with @ashl3y-shen.bsky.social , @b4n1shed.bsky.social and Asheer Malhotra

08.03.2025 08:54 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
a man in a red jacket is dancing in a living room with the words `` happy dance '' . ALT: a man in a red jacket is dancing in a living room with the words `` happy dance '' .
07.03.2025 20:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Honored and excited to be speaking at @pivotcon.bsky.social again this year! πŸŽ‰ Huge shoutout to the co-authors @_vventura, @b4n1shed.bsky.social and @asheermalhotra β€”couldn’t have done this research without you! Looking forward to seeing everyone in MΓ‘laga.

This year I must join the Karaoke!πŸ˜†

07.03.2025 19:55 β€” πŸ‘ 6    πŸ” 2    πŸ’¬ 1    πŸ“Œ 1
Preview
5 Things You Must Check Before Selling On eBay, Facebook Or Etsy Do this now before using any online marketplace.

5 Things You Must Check Before Selling On eBay, Facebook Or Etsy

www.forbes.com/sites/zakdof...

25.02.2025 16:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Your item has sold! Avoiding scams targeting online sellers There are many risks associated with selling items on online marketplaces that individuals and organizations should be aware of when conducting business on these platforms.

Just published a new blog on many of the threats and scams targeting sellers on online marketplaces like Ebay, Reverb, etc. along with recommendations for people using these platforms. Check it out! #phishing #infosec

25.02.2025 11:39 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Elon Musk’s DOGE Posts Classified Data On Its New Website β€œPeople are scrambling” to see if their sensitive information has been accessed by Musk’s programmers, said one federal intelligence employee.

They posted SECRET//NOFORN documents on their site related to IC headcount.

Those of you reading this who have held a clearance know what a colossal no-no this is.

14.02.2025 20:52 β€” πŸ‘ 13    πŸ” 7    πŸ’¬ 1    πŸ“Œ 0
Preview
Anyone Can Push Updates to the DOGE.gov Website "THESE 'EXPERTS' LEFT THEIR DATABASE OPEN."

Scoop: The databases powering DOGE.gov are insecure, and people outside the government have already pushed their own updates to the site to prove it:

www.404media.co/anyone-can-p...

14.02.2025 06:44 β€” πŸ‘ 14518    πŸ” 5958    πŸ’¬ 409    πŸ“Œ 1137

REPOST if you support our federal workforce and know how dedicated they are to their jobs. Show them you appreciate them!

14.02.2025 01:15 β€” πŸ‘ 35414    πŸ” 21233    πŸ’¬ 593    πŸ“Œ 685
DOGE as a National Cyberattack - Schneier on Security In the span of just weeks, the US government has experienced what may be the most consequential security breach in its historyβ€”not through a sophisticated cyberattack or an act of foreign espionage, b...

DOGE as a National Cyberattack www.schneier.com/blog/archive...

13.02.2025 14:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
EFF Sues OPM, DOGE and Musk for Endangering the Privacy of Millions NEW YORKβ€”EFF and a coalition of privacy defenders led by Lex Lumina filed a lawsuit today asking a federal court to stop the U.S. Office of Personnel Management (OPM) from disclosing millions of Ameri...

EFF Sues OPM, DOGE and Musk for Endangering the Privacy of Millions www.eff.org/press/releas...

12.02.2025 13:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Russian bulletproof hosting service Zservers sanctioned by US for LockBit coordination The U.S., the U.K. and Australia sanctioned Russia-based Zservers, connecting the company's internet hosting services to the LockBit ransomware operation.

The U.S. sanctioned #Zservers -- a Russian bulletproof hosting service used to facilitate ransomware attacks by #LockBit

therecord.media/zservers-rus...

12.02.2025 01:20 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@b4n1shed is following 20 prominent accounts